CLI 1.20.0 no longer requires Python
The Cloudsmith CLI now ships as a standalone, self-contained binary for Linux, macOS, and Windows. This eliminates its dependency on a local Python environment. The CLI includes a new one-line installer, a refreshed Homebrew tap and Docker image, and updated GitHub Actions, Azure DevOps, and CircleCI integrations…
Strengthening security together: Updating our bug bounty platform
At Cloudsmith, we recognize that security is a team sport. Meaningful improvements to our platform have come from researchers and security professionals who take the time to find issues and report them to us responsibly. Today, we're launching a new bug bounty platform - now live at bounties.cloudsmith.com - built to make it faster, clearer, and more rewarding to submit security-related bugs to Cloudsmith…
CLI v1.19.0: Authenticate automatically with OIDC and Docker credential discovery
The Cloudsmith CLI now eliminates the need for static API keys in CI/CD pipelines by automatically discovering OpenID Connect (OIDC) credentials for all major CI/CD platforms and includes a Docker credential helper to automatically authenticate to Cloudsmith registries…
Hardened images tab for configuring upstreams
The new Hardened images tab lets you proxy and cache hardened, minimal container images without manual format/URL entry…
Cloudsmith API keys are now detectable by GitHub secret scanning
Cloudsmith has joined the GitHub secret scanning partner program. This integration helps prevent unauthorized use of your API keys by automatically detecting exposed keys before they can be exploited…
Dark mode now available for Cloudsmith docs
Cloudsmith Docs now supports dark mode, reducing eye strain when moving between the product and documentation. Toggle it manually in the footer, or let it follow your system theme…
Manage policies as code with Terraform
Cloudsmith's Terraform provider (v0.0.75) now supports full lifecycle management of policies and policy actions as code…
Create and manage connected repositories with Terraform
With the new cloudsmith_connected_repository resource for the Cloudsmith Terraform provider, you can define connected repository configurations in code alongside the rest of your Cloudsmith infrastructure…
Align npm dist-tags with upstream registries
By default, Cloudsmith assigns the `latest` dist-tag to the package with the highest semantic version number, which may not match what the upstream registry considers `latest`. A new per-repository setting, npm upstream tags take precedence, lets upstream distribution tags (dist-tags) override Cloudsmith’s semantic versioning (SemVer)-based tag assignment…
Private Broadcasts are now generally available
Private Broadcasts lets you put your brand front and center throughout the entire distribution experience, distributing software securely to your partners, customers and internal users through your own branded portal. Full customization and built-in analytics give you control over the experience and visibility into adoption, while entitlement tokens keep access tightly managed, so your software reaches exactly the right people…